github Studio-42/elFinder 2.1.70
Version 2.1.70

3 hours ago

Version 2.1.70

  • Security: Fix CSRF protection for the netmount command
  • Security: Fix MIME validation during ZIP archive extraction
  • Security: Require cURL for URL uploads to prevent SSRF protection bypass in the fsock_get_contents() fallback
  • Fix postMessage origin bypass and playsound DOM XSS

For technical details of [Security:], please refer to the published GitHub Security Advisories.

Full Changelog: 2.1.69...2.1.70

Don't miss a new elFinder release

NewReleases is sending notifications on new releases.